Runs in your browser — nothing you paste is uploaded.
Gravatar URL & Email Hash
Turn an email address into its Gravatar hash and avatar URL. WordPress and many apps identify avatars by the hash of the email, so you never expose the address itself. The hash is computed in your browser — the email is not uploaded.
Loading the preview fetches the image from gravatar.com, which reveals the hash to Gravatar (that's how avatars work). The email itself is never sent.
How the hash is made
Gravatar trims surrounding whitespace and lowercases the email, then hashes it. The original service uses MD5; the newer REST API uses SHA-256. Both are shown — most avatar URLs still use the MD5 form.
The URL options
Size (s=) sets the pixel dimensions (1–2048). Default (d=) picks the fallback when someone has no Gravatar — a generated icon set, a blank pixel, or 404 to return no image. Rating (r=) caps the maximum content rating served.
Privacy
The email is normalized and hashed with crypto.subtle and a small MD5 routine entirely in your browser — it is never uploaded. Only when you click Show avatar preview does the hash go to gravatar.com to fetch the picture. Need a raw MD5/SHA of arbitrary text instead? Use the Hash generator.
Frequently asked questions
MD5 or SHA-256 — which does Gravatar use?
The classic avatar URL uses the MD5 of the normalized email; Gravatar's newer REST API uses SHA-256. Both are shown here — most avatar image URLs still use MD5.
Is my email address exposed?
No. The email is lowercased, trimmed and hashed in your browser; only the hash is ever used. Avatar URLs contain the hash, not the address, which is the whole point of Gravatar.